A Framework for Evaluating Client Privacy Leakages in Federated Learning

被引:42
|
作者
Wei, Wenqi [1 ]
Liu, Ling [1 ]
Loper, Margaret [1 ]
Chow, Ka-Ho [1 ]
Gursoy, Mehmet Emre [1 ]
Truex, Stacey [1 ]
Wu, Yanzhao [1 ]
机构
[1] Georgia Inst Technol, Atlanta, GA 30332 USA
来源
关键词
Privacy leakage attacks; Federated learning; Attack evaluation framework;
D O I
10.1007/978-3-030-58951-6_27
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Federated learning (FL) is an emerging distributed machine learning framework for collaborative model training with a network of clients (edge devices). FL offers default client privacy by allowing clients to keep their sensitive data on local devices and to only share local training parameter updates with the federated server. However, recent studies have shown that even sharing local parameter updates from a client to the federated server may be susceptible to gradient leakage attacks and intrude the client privacy regarding its training data. In this paper, we present a principled framework for evaluating and comparing different forms of client privacy leakage attacks. We first provide formal and experimental analysis to show how adversaries can reconstruct the private local training data by simply analyzing the shared parameter update from local training (e.g., local gradient or weight update vector). We then analyze how different hyperparameter configurations in federated learning and different settings of the attack algorithm may impact on both attack effectiveness and attack cost. Our framework also measures, evaluates, and analyzes the effectiveness of client privacy leakage attacks under different gradient compression ratios when using communication efficient FL protocols. Our experiments additionally include some preliminary mitigation strategies to highlight the importance of providing a systematic attack evaluation framework towards an in-depth understanding of the various forms of client privacy leakage threats in federated learning and developing theoretical foundations for attack mitigation.
引用
收藏
页码:545 / 566
页数:22
相关论文
共 50 条
  • [31] An Efficient Differential Privacy Federated Learning Scheme with Optimal Adaptive Client Number K
    Wang, Jian
    Zhang, Mengwei
    [J]. Proceedings of SPIE - The International Society for Optical Engineering, 2023, 12587
  • [32] Privacy-Preserving Federated Learning With Improved Personalization and Poison Rectification of Client Models
    Cao, Yihao
    Zhang, Jianbiao
    Zhao, Yaru
    Shen, Hong
    Huang, Haoxiang
    [J]. IEEE Transactions on Information Forensics and Security, 2024, 19 : 8845 - 8859
  • [33] PFLF: Privacy-Preserving Federated Learning Framework for Edge Computing
    Zhou, Hao
    Yang, Geng
    Dai, Hua
    Liu, Guoxiu
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1905 - 1918
  • [34] Privacy-preserving federated learning framework in multimedia courses recommendation
    YangJie Qin
    Ming Li
    Jia Zhu
    [J]. Wireless Networks, 2023, 29 : 1535 - 1544
  • [35] Privacy-Preserving and Verifiable Federated Learning Framework for Edge Computing
    Zhou, Hao
    Yang, Geng
    Huang, Yuxian
    Dai, Hua
    Xiang, Yang
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 565 - 580
  • [36] Robust privacy-preserving federated learning framework for IoT devices
    Han, Zhaoyang
    Zhou, Lu
    Ge, Chunpeng
    Li, Juan
    Liu, Zhe
    [J]. INTERNATIONAL JOURNAL OF INTELLIGENT SYSTEMS, 2022, 37 (11) : 9655 - 9673
  • [37] Privacy-Preserving Asynchronous Federated Learning Framework in Distributed IoT
    Yan, Xinru
    Miao, Yinbin
    Li, Xinghua
    Choo, Kim-Kwang Raymond
    Meng, Xiangdong
    Deng, Robert H. H.
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (15) : 13281 - 13291
  • [38] A Game-theoretic Framework for Privacy-preserving Federated Learning
    Zhang, Xiaojin
    Fan, Lixin
    Wang, Siwei
    Li, Wenjie
    Chen, Kai
    Yang, Qiang
    [J]. ACM TRANSACTIONS ON INTELLIGENT SYSTEMS AND TECHNOLOGY, 2024, 15 (03)
  • [39] Privacy-preserving federated learning framework in multimedia courses recommendation
    Qin, YangJie
    Li, Ming
    Zhu, Jia
    [J]. WIRELESS NETWORKS, 2023, 29 (04) : 1535 - 1544
  • [40] Artificial Identification: A Novel Privacy Framework for Federated Learning Based on Blockchain
    Ouyang, Liwei
    Wang, Fei-Yue
    Tian, Yonglin
    Jia, Xiaofeng
    Qi, Hongwei
    Wang, Ge
    [J]. IEEE TRANSACTIONS ON COMPUTATIONAL SOCIAL SYSTEMS, 2023, 10 (06) : 3576 - 3585